Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00405A7F |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0040721E |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00406A36 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00405395 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_023284F7 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02321A5F |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232FB8E |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232CFC2 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232330D |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232702D |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02327005 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E629 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E665 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D66F |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D698 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E6F9 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E6CD |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E734 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232272C |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D71E |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E76E |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D758 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02329784 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_023247F1 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02327463 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E59E |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E5EC |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232DA30 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02320A5C |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02324A41 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02324A81 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02324AE4 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02324B2E |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02324BB4 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232DBC5 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02324819 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E819 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D855 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E844 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D89D |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_023248DD |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D989 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D9D1 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232CFED |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02326FD9 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02324C32 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02321DBE |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03203760 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_032047F1 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320FB8E |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03201A5F |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320CFC2 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320330D |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320702D |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03207005 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320272C |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03203781 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03209784 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320D698 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320E59E |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03207463 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03204B2E |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03204BB4 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03204A41 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03200A5C |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03204A81 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03204AE4 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03204819 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03203849 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_032048DD |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320CFED |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03206FD9 |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03201DBE |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03204C32 |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232F695 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232FB8E NtResumeThread, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232CFC2 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D210 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D295 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D2E0 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D311 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D046 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D0E6 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D0D1 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232D13C NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02328A05 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232CFED NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320F695 NtProtectVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320CFC2 NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320D311 NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320D210 NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320D295 NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320D2E0 NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320D13C NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320D046 NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320D0E6 NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320D0D1 NtAllocateVirtualMemory, |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320CFED NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00405241 pushfd ; retf |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00405A57 push 0000004Bh; retf |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00408858 push 00000018h; ret |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0040A864 push esi; iretd |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00405A7F push ebx; ret |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00406A27 push es; iretd |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00405AD4 push ebx; ret |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_00405CFE push 18FEA023h; retf |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_004086A1 push edx; iretd |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232816B push ss; iretd |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_023281D4 push ss; iretd |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232564B push ebp; iretd |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232A7C6 push ecx; ret |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02321834 push es; retf |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02322EF5 push ebp; iretd |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02320F16 push edx; ret |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_02322F48 pushad ; iretd |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320816B push ss; iretd |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320A7C6 push ecx; ret |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320564B push ebp; iretd |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03201834 push es; retf |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03200F16 push edx; ret |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03202F48 pushad ; iretd |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_03202EF5 push ebp; iretd |
Source: 171121_PDF.exe, 00000000.00000002.498429562.0000000003A0A000.00000004.00000001.sdmp, ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V Guest Shutdown Service |
Source: 171121_PDF.exe, 00000000.00000002.498429562.0000000003A0A000.00000004.00000001.sdmp, ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V Remote Desktop Virtualization Service |
Source: ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: vmicshutdown |
Source: 171121_PDF.exe, 00000000.00000002.498429562.0000000003A0A000.00000004.00000001.sdmp, ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V Volume Shadow Copy Requestor |
Source: 171121_PDF.exe, 00000000.00000002.498429562.0000000003A0A000.00000004.00000001.sdmp, ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V PowerShell Direct Service |
Source: 171121_PDF.exe, 00000000.00000002.498429562.0000000003A0A000.00000004.00000001.sdmp, ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V Time Synchronization Service |
Source: ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: vmicvss |
Source: 171121_PDF.exe, 00000000.00000002.498410892.0000000003940000.00000004.00000001.sdmp, ieinstal.exe, 0000000F.00000002.544039436.0000000003690000.00000004.00000001.sdmp | Binary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe |
Source: 171121_PDF.exe, 00000000.00000002.498429562.0000000003A0A000.00000004.00000001.sdmp, ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V Data Exchange Service |
Source: ieinstal.exe, 0000000F.00000002.544039436.0000000003690000.00000004.00000001.sdmp | Binary or memory string: ntdllkernel32C:\Program Files\Qemu-ga\qemu-ga.exeC:\Program Files\qga\qga.exeuser32psapi.dllMsi.dllPublisherwininet.dllMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36shell32advapi32TEMP=\vagabo.exe\CUSCONINESoftware\Microsoft\Windows\CurrentVersion\RunSkuffejernenesco2 |
Source: 171121_PDF.exe, 00000000.00000002.498429562.0000000003A0A000.00000004.00000001.sdmp, ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V Heartbeat Service |
Source: 171121_PDF.exe, 00000000.00000002.498429562.0000000003A0A000.00000004.00000001.sdmp, ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V Guest Service Interface |
Source: 171121_PDF.exe, 00000000.00000002.498410892.0000000003940000.00000004.00000001.sdmp | Binary or memory string: ntdllkernel32C:\Program Files\Qemu-ga\qemu-ga.exeC:\Program Files\qga\qga.exeuser32psapi.dllMsi.dllPublisherwininet.dllMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36shell32advapi32TEMP=ProgramFiles=\internet explorer\ieinstal.exewindir=\syswow64\msvbvm60.dllProgramFiles=\internet explorer\ieinstal.exewindir=\syswow64\msvbvm60.dll |
Source: ieinstal.exe, 0000000F.00000002.544366173.0000000004F3A000.00000004.00000001.sdmp | Binary or memory string: vmicheartbeat |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_023296BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232E59E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232C982 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\171121_PDF.exe | Code function: 0_2_0232BEA2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_032096BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320E59E mov eax, dword ptr fs:[00000030h] |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320C982 mov eax, dword ptr fs:[00000030h] |
Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe | Code function: 15_2_0320BEA2 mov eax, dword ptr fs:[00000030h] |